Authors: Jamie Douglas, Andy Andrews and Matt O’Sullivan
Across this series, The Human Factor: Cybersecurity’s Blind Spot, Why it persists – and how to address it, one argument runs consistently: the defining variable in cybersecurity isn’t technology – it’s human behaviour. Organisations keep investing in tools while structuring work around how people *should* behave, not how they *actually do*. These blog posts explore why that gap exists and what it takes to close it.
Part One: “Cybersecurity Isn’t a Technical Problem, It’s a Human One”
Part Two: “From Weakest Link to First Line of Defence: Reframing People in Cybersecurity”
Part Three: “From Insight to Action: Building Behaviour-Led Cyber Resilience”
Introduction

Part One and Part Two of this series established why behaviour matters and why organisations must treat human capability as a strategic asset. Part Three now turns insight into practice: how organisations can deliberately design structures for secure behaviour.
The gap between intent and outcome
Most leaders already acknowledge the human dimension of cyber risk. Some fund training, run phishing simulations and deliver awareness campaigns; but plenty of organisations skip that investment altogether. Ipsos’s Cyber Security Breaches Survey 2025/2026 found that only 19% of UK businesses and 17% of charities had provided any cybersecurity training in the previous 12 months, meaning the majority hadn’t run any in the past year. 1
And where training does happen, sustained behaviour change often remains elusive. A 2025 meta‑analysis by Prümmer, van Steen and van den Berg found that cybersecurity training tends to improve knowledge and attitudes more than it changes long‑term behaviour in real‑world conditions. 2
This highlights the intent–outcome gap. It persists not because organisations lack effort, but because their approach rests on a flawed assumption: that behaviour is only driven by knowledge.
But behaviour is also driven by context – pressures, incentives, friction, ambiguity and social cues. Knowing the right thing to do and doing it under deadline pressure or authority cues are very different challenges.
As Part Two emphasised, people act on habit, context, and prior experience, not on policy recall.
A four‑layer model for behaviour‑led cyber resilience
Organisations working toward behaviour‑led resilience can use four interconnected layers:
- Define the behaviours that matter
- Build role‑based capability
- Design environments that reinforce secure behaviour
- Measure what drives outcomes
These layers are sequential and interdependent. Behaviour must be defined before it can be developed; capability erodes without supportive environments; and measurement without behavioural clarity produces the same lagging indicators organisations already over‑rely on.
Together, these layers shift cybersecurity from a compliance function to an organisational capability; one that improves continuously rather than reacting only when something goes wrong.
1. Define the behaviours that matter
Most organisations define cybersecurity through policies and controls. Far fewer define it in terms of observable, demonstrable behaviour, and that gap creates ambiguity at the point of decision. A Fortra/Ipsos study found that 52% of employees across France, the UK, Canada, Australia and the US did not see cybersecurity as part of their role. 3
Telling people to “be vigilant” offers little practical guidance when they face an urgent request from a senior stakeholder, a suspicious but plausible email, or a trade‑off between speed and verification. Without specific behavioural expectations, people default to whatever the environment implicitly rewards.
Defining cyber‑resilient behaviours concretely changes that. It’s the same principle behind the job and skill profiling work carried out at Lexonis: translating a role into the specific behaviours that separate strong performance from weak, so “be secure” becomes something people can identify with and act on. For example:
- In finance, that might mean verifying every payment change through a secondary channel
- In sales, it means checking unexpected links from clients before responding
- For executives, it means challenging unusual requests even under time pressure – the same principle, applied differently by role.
So, security isn’t abstract, it is observable role-specific behaviour under real conditions. If behaviour is not defined, it cannot be developed or measured.
At Lexonis, we take this a step further; defining behavioural expectations (indicators) in detail across different departments, job families, and role levels. This level of clarity anchors behaviour in operational reality.
| Finance Team Cybersecurity Awareness | Knowledge of cyber risks affecting finance operations; ability to recognise, prevent, report and respond appropriately to threats involving financial data, systems and transactions. |
| Level | Behavioural indicators |
| Foundational | Recognises common finance‑related cyber risks
Follows approved procedures for access, data handling and reporting Identifies suspicious messages or unusual payment requests Escalates concerns promptly |
| Working | Applies secure practices during transaction processing and stakeholder communication
Verifies unusual payment changes Uses approved systems and secure channels Challenges suspicious requests Supports colleagues in secure working practices |
| Expert | Evaluates cyber risks within finance processes
Guides teams on secure handling of financial data Identifies recurring risky behaviours or control gaps Collaborates with security, risk and audit teams Recommends improvements to reduce fraud and data exposure |
| Strategic | Sets cybersecurity expectations for finance
Sponsors targeted awareness initiatives Influences senior stakeholders on finance‑related cyber risks Aligns finance security with enterprise risk management Monitors emerging threats and updates priorities |
2. Build role‑based capability
Once behaviours are defined, the next question is where the gaps exist. A clear job skills profile makes that visible. It shows which people, in which roles, need which capability built so that training is targeted at a real gap rather than delivered as a blanket exercise.
Generic awareness training treats all roles as interchangeable, while targeted training recognises cyber risks are not generic. A developer, a finance controller and a sales manager face different threats, operate under different pressures, and make decisions in different contexts. Industry threat intelligence, including IBM’s X‑Force reporting, consistently shows that business‑facing roles are heavily targeted for social engineering, while technical roles such as developers are frequently targeted for credential theft and access to code repositories.4
Capability development must be equally differentiated. Moving from one‑size‑fits‑all awareness to targeted performance enablement requires scenario-based simulations. Models that mirror real decisions, provide contextual examples drawn from each department’s own risk landscape, and coaching and feedback that buildjudgement rather than memory.
3. Design an environment that reinforces behaviour
Even highly capable individuals can fail in poorly designed systems. Many organisations attempt to change behaviour without changing the conditions in which behaviour occurs.
Research by CybSafe and the National Cybersecurity Alliance highlights widespread confusion and frustration with security advice, and growing signs of “cybersecurity fatigue” as people struggle to reconcile security requirements with everyday work. They report 44% of people feeling overwhelmed by security information. 5
Behaviour is shaped by friction, incentives and signals. If performance metrics reward speed over accuracy, people will take shortcuts. If escalation processes are slow or ignored, people stop escalating. If secure procedures are significantly more complex than insecure workarounds, the workaround wins.
“The secure option must be the easiest viable option.”
What this looks like in practice
In practice, designing for the “easiest viable option” means reducing friction in secure workflows, embedding decision support at the point of action and ensuring that leadership behaviour reinforces, rather than contradicts, what the organisation formally expects. For example:
- Single sign‑on and MFA are streamlined rather than obstructive
- Suspicious email reporting is reduced to a single click
- Approved collaboration tools are easier to use than external alternatives
- Security prompts appear at the point of decision
- Automated patching reduces cognitive load
The 2026 EY Global Cybersecurity Leadership Insights Study into visible assets (systems, tools and processes) reinforces that secure behaviour depends on the environment. ⁶ If workplace tools are confusing or poorly connected, people are forced to guess. If tools are clear and well‑designed, secure behaviourbecomes the natural choice.
4. Measure what drives outcomes
What gets measured gets managed and many organisations are measuring the wrong things.
Standard metrics such as patch compliance, mean time to detect, and endpoint coverage are important, but they are lagging indicators. They show what has already happened, not why it happened.
Research among CISOs, including YL Ventures’ CISO Reporting Landscape, shows that reporting remains dominated by technical and lagging indicators such as breach trends, patching timeframes and tool coverage, with behavioural metrics still largely absent. ⁷
If behaviour drives outcomes, measurement must shift towards leading indicators, i.e. signals that reveal issues before they become incidents:
- Frequency and quality of escalations
- How decisions are made under pressure
- Where controls are bypassed and why
- How teams respond to weak or incomplete signals
- How teams learn and adapt after incidents
These measures are harder to quantify than patch rates, but they are more valuable because they reveal the conditions that create risk and can show where cyber resilience is improving.
What behaviour‑led resilience looks like
Behaviour‑led cyber resilience is still emerging, but its impact is increasingly visible. Organisations become more resilient when they focus not only on controls and incidents, but also on the everyday behaviours that shape how risk is recognised, escalated, contained and learned from.
This approach aligns with the UK National Cyber Security Centre’s cybersecurity culture principles⁸ and behavioural science models such as COM‑B⁹, which emphasise capability, opportunity and motivation.
When organisations work across these four layers, the intended shift should be visible not only in incident data, but in how security is discussed, owned and practised day to day. Security discussions shift from compliance to decision quality. Training becomes continuous and role-based rather than an annual event. Leadership engages with cyber risk as a business issue, not a technical one. And employees start acting with ownership rather than obligation.
Over time, organisations should surface weak signals earlier, contain failures more effectively and support people to respond under pressure. Cyber resilience becomes the capacity to detect, adapt and recover; not the absence of incidents.
A behaviour-led culture – a strategic advantage
The trajectory across this 3-part series has been consistent: cybersecurity is a socio‑technical system, risk lives in the interaction between people and controls, and behaviour determines outcomes.
Organisations that treat cybersecurity as primarily technical will likely continue to see diminishing returns. Those that treat human behaviour as a strategic capability can build an advantage attackers cannot easily replicate.
Attackers already exploit human behaviour deliberately e.g. urgency, authority, familiarity. Verizon’s Data Breach Investigations Reports repeatedly show that the human element is present in the majority of breaches, whether through phishing, misconfiguration or misuse of credentials. ¹⁰Cyber defenders must apply the same level of behavioural understanding to their own people.
Conclusion: Designing for human reality
The question is no longer whether people matter in cybersecurity. That case has been made. The question is whether organisations are willing to design for that reality. Training alone is insufficient. Tools alone are insufficient. Policies alone cannot sustain behaviour.
Cyber resilience has to be multifaceted. It requires systems where people are equipped to make sound judgements, where environments support those judgements, and behavioural capability is defined, measured and continuously reinforced.
Cyber resilience is not a destination; it is a capability forged through preparation and revealed under pressure.
Throughout this 3-part series, the message has been resolute – attackers already exploit human behaviour deliberately, precisely, and at scale. Defenders can no longer afford to leave that same behaviour to chance.
The organisations that close this gap won’t be the ones with the most tools. They will be the ones that define, build, and measure human capability with the same rigour they apply to technology.
At Lexonis, this is our focus: helping organisations move beyond awareness and tooling toward the clear definition, development and measurement of the human capabilities that drive meaningful security outcomes. In practice, that means building job skill profiles that define what ‘good’ looks like role by role, spotting where the gaps are and using that insight to target development. Over time, that same insight helps shape a culture built around the right behaviours, rather than just the right policies.
Building Behaviour-Led Cyber Resilience is a journey. If you’re ready to turn security behaviours into a lasting organisational strength, we’d be delighted to explore how with you.
Want to take the next step?
Book a chat and a demo with Lexonis today.
References
¹Ipsos (2025/26), The UK Government’s Cyber Security Breaches Survey 2025/26.
²Prümmer, J., van Steen, T., & van den Berg, B. (2025). Assessing the effect of cybersecurity training on end users: A meta-analysis. Institute of Security and Global Affairs.
³Fortra / Ipsos (2023), From Data Protection to Cyber Culture, Terranova Security.
⁴ IBM Security. X‑Force Threat Intelligence Index.
⁵CybSafe and the National Cybersecurity Alliance (NCA).
⁶ EY (2026). Global Cybersecurity Leadership Insights Study.
⁷ YL Ventures (2024). CISO Reporting Landscape.
⁸National Cyber Security Centre (UK). Cyber Security Culture Principles.
⁹Decision Labs (2025). The COM‑B Model for Behavior Change.